Skip to main content

Vendor archive

openssl CVEs

Beta · best-effort

292 CVEs tagged to vendor openssl19 Critical, 91 High, 166 Medium, 16 Low, 0 Unrated.

CVE-2015-0208

Published Mar 19, 2015

The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0207

Published Mar 19, 2015

The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of independent data streams, which allows remote attackers to…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0206

Published Jan 9, 2015

Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory con…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-0205

Published Jan 9, 2015

The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0204

Published Jan 9, 2015

The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA down…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
28.8
Vendor/product tagsBeta · best-effort

CVE-2014-8275

Published Jan 9, 2015

OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3572

Published Jan 9, 2015

The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrad…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3571

Published Jan 9, 2015

OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a cr…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2014-3570

Published Jan 9, 2015

The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it eas…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3569

Published Dec 24, 2014

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attack…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3568

Published Oct 19, 2014

OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3567

Published Oct 19, 2014

Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j allows remote attackers to cause a denial of ser…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3513

Published Oct 19, 2014

Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted handshak…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5139

Published Aug 13, 2014

The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client applica…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3512

Published Aug 13, 2014

Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a denial of service (application crash)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3511

Published Aug 13, 2014

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3510

Published Aug 13, 2014

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote DTLS servers to cause a denial…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3509

Published Aug 13, 2014

Race condition in the ssl_parse_serverhello_tlsext function in t1_lib.c in OpenSSL 1.0.0 before 1.0.0n and 1.0.1 before 1.0.1i, when multithreading and session resumption are used…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3508

Published Aug 13, 2014

The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when pretty printing is used, does not ensure t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3507

Published Aug 13, 2014

Memory leak in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of serv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3506

Published Aug 13, 2014

d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory con…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3505

Published Aug 13, 2014

Double free vulnerability in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3470

Published Jun 5, 2014

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allow…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
24.1
Showing 176-200 of 292 CVEsPage 8 of 12